Live data from Hacker News

Whistleblower: Ubiquiti Breach “Catastrophic”

krebsonsecurity.com

701–710 of 815 posts

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#701

This company is a disaster it seems, and I have just setup my whole home infrastructure and home security aound their products... They where the most recommended brand when I was shopping for new stuff a year ago.

Our "CTO" was told only last week by someone from the company that helps us with ISO 27001 that we shouldn't use whatever we've got, but get Ubiquity instead, because it was safer...

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#702

Earlier quoted context omitted.

> Note, however, that roaming between APs is a feature of the 802.11 standard; In theory yes, but man do a lot of devices have terrible roaming heuristics. "I can still see beacons so id better stay here even though i havent received a packet in the last minute. Wouldnt want to pay the time cost of associating with that other BSS that has 5X the signal"

Do people _really_ need wifi roaming in their homes? I have multiple cheap APs setup in my house using the same SSID and it's fine. As long as I'm not holding a realtime conversation and moving around between APs I never have any problems. And since I almost never hold a Skype call while walking through my house I almost never have any issues.

Also as long as you don't have big bags of attenuating water (people) moving between you and your AP you also funny need roaming.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#703

Earlier quoted context omitted.

> Note, however, that roaming between APs is a feature of the 802.11 standard; In theory yes, but man do a lot of devices have terrible roaming heuristics. "I can still see beacons so id better stay here even though i havent received a packet in the last minute. Wouldnt want to pay the time cost of associating with that other BSS that has 5X the signal"

Do people _really_ need wifi roaming in their homes? I have multiple cheap APs setup in my house using the same SSID and it's fine. As long as I'm not holding a realtime conversation and moving around between APs I never have any problems. And since I almost never hold a Skype call while walking through my house I almost never have any issues.

Yep, stupid L-shaped house where the inner curve is a damn Faraday Cage. NOTHING goes through.

If I'm in the living room and need to move to the other end of the house to get away from family-related noise, the device needs to roam between two APs.

Unifi handles this without any issues.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#704

Earlier quoted context omitted.

If admin login is using weak credentials, it is by definition not a secure backend. Password/credential management and mandatory MFA are ALWAYS part of security due diligence for suppliers.

Except if it is awscli creds, then of course there is no MFA.

AWS STS solves this problem.

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#705

Earlier quoted context omitted.

Surely 802.11r has a purpose, yes?

Yes, roaming by sharing SSID and passcode is a world of pain. 802.11r solves all those pains, I've been using it on OpenWRT for months without a glitch.

I have a couple of AP AC Lites running openwrt and 802.11r, works fine except on Xiaomi phones apparently... I never tried the unifi though, flashed openwrt within 15 minutes of receiving the APs

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#706

Earlier quoted context omitted.

Mikrotik is amazing, for what you get. But of a learning curve but worth the effort, I've seen large scale wireless networks crossing mountains with their kit.

I am not a fan of Mikrotik, the UI is not nice and the defaults are not smart. I have seen professionals make mistakes on them several times.

I personally love the UI. It's basically a very readable 1:1 map of the CLI

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#707

Earlier quoted context omitted.

Disclaimer: worked for Meraki (now Cisco Meraki) for several years. Generally, halfway decent wireless APs are all targeted at the enterprise market. Consumer hardware is a brutal race to the bottom, as lay consumers aren't qualified to compare options based on anything but price and UI. Ubiquiti was an outlier in trying to bring enterprise features to the consumer market The problem for enthusiasts and small busines…

Worth noting that Meraki have a small business option now: https://www.meraki-go.com/

Says “cloud managed” on every piece of equipment. Do you know if that’s optional?

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#709
post #49

Earlier quoted context omitted.

Was shopping for alternatives to my Ubiquiti last night. Seems like there is nothing good out there. Engenius has shit hardware and a cloud controller. Aruba has a cloud controller AND you have to pay for a license. Cisco makes you pay for a license. TP-Link is cloud-based. WTF. Does anyone have a decent WAP where I can use PoE, deploy like 5 of them and have them support roaming between APs, all managed locally? Is…

Peplink seems pretty good; they do have a Cloud:tm: management offering called InControl2 but as far as I'm aware it's entirely optional. I've had good luck configuring everything via the local UI. My setup is a Balance Two + a few One AX APs.

+1 for Peplink, Surprised more people haven't mentioned them

Re: Whistleblower: Ubiquiti Breach “Catastrophic”

#710

Earlier quoted context omitted.

how do you enable 802.11r on openwrt? on which model of router

Install the wpad pkg and 802.11r should show up in wireless config screens. See https://forum.openwrt.org/t/802-11r-fast-roaming-in-luci/117...

Pretty much that. It's also very simple nowadays. you just tick the box on the Wireless Security tab, and check that the mobility domain match between all the APs - it should by default, I think it's derived from the SSID.
Post reply on HN